6 nfpa 72 requirements, 7 nfpa 85 requirements – Rockwell Automation T8094 8000 Series TMR System Safety Manual User Manual

Page 47

Advertising
background image

SAFETY MANUAL

D oc N umber T8094
I ssue 27 – June 2013

Page 26 of 103

3.2.5 EN 60204 Category 0 & 1 Configurations

The system is fully compliant for use with category 0 application (de-energise to trip).

Category 1 configurations require a controlled stop with power available to the machine
actuators to achieve the stop and then removal of power.

The 8000 system has a defined internal fail-safe state as de-energised. This could
result in the defined shutdown delay being shortened in some cases of I/O failure, CPU
failure or loss of power to the system.

3.2.6 NFPA 72 Requirements

The 8000 system is certified to be used in NPFA 72 compliant fire alarm systems.

The systems should be designed and integrated in accordance with NFPA 72. In
particular the following shall be applied.

Unless otherwise permitted, all field loops to sensors and actuators, inter-system

and subsystem signal wiring, and communications links shall be line monitored for
single open & short circuits. The fault condition and the restoration to normal shall
be automatically indicated within 200seconds.

3.2.7 NFPA 85 Requirements

The 8000 system is certified to be used in NFPA 85 compliant systems.

The systems should be integrated in accordance with NFPA 85. In particular the
following shall be applied.

The operator shall be provided with a dedicated manual switch that shall
independently and directly actuate the safety shutdown trip relay. At least one
identified manual switch shall be located remotely from the boiler where it can be
reached in case of emergency.

The burner management system shall be provided with independent logic,
independent input/output systems, and independent power supplies and shall be a
functionally and physically separate device from other logic systems, such as the
boiler or HRSG control system.

Momentary Closing of Fuel Values. Logic sequences or devices intended to cause
a safety shutdown, once initiated, shall cause a burner or master fuel trip, as
applicable, and shall require operator action prior to resuming operation of the
affected burner(s). No logic sequence or device shall be permitted that allows
momentary closing and subsequent inadvertent reopening of the main or ignition
fuel valves.

Documentation shall be provided to the owner and operator, indicating that all
safety devices and logic meet the requirements of the application.

System response time (i.e. throughput) shall be sufficiently short to prevent
negative effects on the application.

Advertising